[CLSA-2026:1780306192] Fix CVE(s): CVE-2026-6914
Type:
security
Severity:
Important
Release date:
2026-06-01 09:30:05 UTC
Description:
* SECURITY UPDATE: Denial of service via MD5 checksum of malformed BSON object with deprecated ByteArray type - debian/patches/CVE-2026-6914.patch: Add ssize>=4 bounds check in binDataClean() for the ByteArrayDeprecated branch and guard md5_append() call with len>0 check in CmdFileMD5 - CVE-2026-6914
CVEs fixed:
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els8_amd64.deb
    sha:d337861c3428c1669da3729193c2a36b78e1bd3b
  • mongodb6-mongos_6.0.26-1+tuxcare.els8_amd64.deb
    sha:a6832c398fcbf0e68113e9dbe8a562f60edaaf60
  • mongodb6-server_6.0.26-1+tuxcare.els8_amd64.deb
    sha:0923e17b35591d4ce0962e2bebe0589b73498cc9
  • mongodb6-shell_6.0.26-1+tuxcare.els8_amd64.deb
    sha:f1ade46041aa7c189881c4791eaa8b1406193352
  • mongodb6_6.0.26-1+tuxcare.els8_arm64.deb
    sha:fa4e1a1f9abdec6f76e2f1c4c83058c1095fb0b5
  • mongodb6-mongos_6.0.26-1+tuxcare.els8_arm64.deb
    sha:a364cd86836b14570ff066295184d6c3c372a885
  • mongodb6-server_6.0.26-1+tuxcare.els8_arm64.deb
    sha:8c0b28a1f94fc47ea0218003b41d3d66c033c50d
  • mongodb6-shell_6.0.26-1+tuxcare.els8_arm64.deb
    sha:0dc2fd231d348e1d9853acc3b59320375fc4ee1b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.